Privacy Policy
Last updated: 29 September 2026
This policy explains what data LevelOne Desk (Staging) (operated by Aap ki Company ka Naam) handles, why, and your choices.
1. Data we process
- Sign-in: name, email address (user principal name) and Microsoft tenant id of people who sign in, provided by Microsoft when they sign in. We never see or store passwords.
- Microsoft 365 directory data, read through Microsoft Graph with the permissions your administrator granted, only when a request needs it: user names, job titles, departments, group memberships, licenses, admin roles, account status and MFA registration status. We do not read mailboxes, files, chats or calendars.
- Helpdesk content: chat messages, requests, approvals and the audit log.
- Billing: handled by Paddle. We receive the subscription status, plan and billing email; card details go only to Paddle.
- Technical: a session cookie to keep you signed in, and short-lived server logs (IP address, request path, time) for security and troubleshooting.
2. How we use it
Only to provide and secure the Service: answering questions, preparing and running approved changes, keeping the audit log, billing and support. We don't sell data, show ads or use your data to train AI models.
3. AI processing
Chat messages and the directory information needed to answer them are sent to our AI provider to generate replies. The provider processes them only to return an answer and states that it does not use API data to train its models. Don't put passwords or other secrets in chat messages.
4. Service providers
- Oracle Cloud Infrastructure: hosting and storage.
- Groq: AI model processing.
- Microsoft: sign-in and Microsoft 365 (your own tenant).
- Paddle: payments, invoices and tax, as Merchant of Record.
5. Security
Each organization's data is kept in its own separate database. Access to Microsoft 365 uses a certificate, not a password. Traffic is encrypted with HTTPS. Temporary passwords created by the Service are shown once to the approving administrator and never stored, logged or emailed.
6. Retention
- Audit logs are kept while your organization uses the Service; how far back you can view them depends on your plan.
- Each person's saved chats are limited to their most recent 100 and can be deleted by them at any time.
- After you cancel or disconnect, email us to delete your organization's data. We delete it within 30 days, except billing records we must keep by law. Backups are overwritten within 14 days.
7. Your rights
You can ask for a copy of your data, a correction or deletion by emailing rehanrajpoot946@gmail.com. Your organization's administrator can also remove the Service's access to Microsoft 365 at any time in Microsoft Entra.
8. Cookies
We use one essential cookie to keep you signed in, and your browser remembers your light or dark theme choice. No advertising or tracking cookies.
9. Changes and contact
We'll post changes on this page and update the date above. Questions: rehanrajpoot946@gmail.com.